Skip to main content

Deploying with Microsoft Intune

Step 1 - Enable Intune Integration in Patch Desktop​

Connect Patch Desktop directly to Intune to upload configuration profiles without manual export or using the Intune web interface.

Optional Integration

Enabling the integration is not required to deploy Alectrona Patch with Intune. You can also choose to export the configuration profile from Patch Desktop and upload it to Intune manually.

Create an Intune App Registration for Patch Desktop Integration
  1. Create an App Registration in Microsoft Entra ID and record the Application (client) ID and Directory (tenant) ID for use in Patch Desktop.
  2. Create a client secret for the App Registration in the Certificates & secrets section and record the value for use in Patch Desktop.
  3. Assign the API permissions listed below to the App Registration and grant admin consent.
  • DeviceManagementConfiguration.Read.All
  • DeviceManagementConfiguration.ReadWrite.All
  • DeviceManagementManagedDevices.Read.All
  • DeviceManagementRBAC.Read.All
  • DeviceManagementRBAC.ReadWrite.All
  • DeviceManagementScripts.Read.All
  • DeviceManagementScripts.ReadWrite.All
  • DeviceManagementServiceConfig.Read.All
  • DeviceManagementServiceConfig.ReadWrite.All
More information about App Registrations and Microsoft Graph API Permissions

Step 2 - Connect Patch Desktop to Intune​

In Patch Desktop, open Settings from the sidebar.

Open Settings Open Settings

Step 3 - Create Your Patch Profile in Patch Desktop​

Use Patch Desktop to build your Alectrona Patch configuration—select apps to keep up to date or install, and customize the end-user experience with branding and notifications—all in one place.

Configure Your License and Initial Settings​

In Patch Desktop, navigate to Configuration > General and enter your Patch License. Click Validate to confirm the license is valid and active. This will unlock the full functionality of Patch Desktop.

Patch Desktop Enter License Patch Desktop Enter License

Choose Your Apps​

With your desired configuration settings in place, navigate to the Patch Catalog inside Patch Desktop and choose the apps you would like to manage. We recommend that you toggle the Update functionality for any apps deployed in your environment. This ensures those apps are kept up to date if they are installed on any endpoints.

Optionally, you can enable Update All which will configure Alectrona Patch to automatically update every third-party app installed on your Macs that exist in the Patch Catalog. For any software titles you prefer to not update, toggle the Update button off for that app which will exclude it from receiving updates from Alectrona Patch.

Patch Desktop Configuration Patch Desktop Configuration

Recommended Settings for Intune

For Microsoft Intune, we recommend toggling both Install and Update for each software title you would like to manage in your environment. Leveraging the Install feature of Alectrona Patch is an easy way to not only keep your managed apps up to date, but ensure all chosen apps are installed on the client Mac if not already installed. This also helps speed up deployment on newly enrolled Macs!

Step 4 - Upload Configuration Profile to Microsoft Intune​

Click Export in the top right of Patch Desktop or choose File > Export mobileconfig to export your configuration profile.

Export Profile Export Profile

Required Permissions​

A Privacy Preferences Policy Control (PPPC) configuration profile (see below) is required to ensure Alectrona Patch functions properly.

Additionally, if you enable the Patch Menu Bar app, deploy a profile that configures Notification Center Alerts or Banners for Patch. Example profiles for persistent alerts or temporary banners are provided below.

Required Profiles

Note: Banners disappear automatically, while alerts remain on screen until dismissed. Choose the profile that matches your desired behavior.

Included in Patch Desktop

Patch Desktop 2.1+ can automatically include these required payloads in the generated Patch Profile, eliminating the need to deploy the profiles separately.

Step 5 - Deploy Alectrona Patch 🎉​

  1. Download and save our install script.
  2. Inside Microsoft Intune, navigate to Devices > macOS > Shell scripts and click Add.
  3. Name the script (e.g. Install Alectrona Patch), upload it, and assign it to devices. Under script settings, toggle Run the script as signed-in user off and Hide script notifications on devices to Yes. The additional settings can be left as Not configured.